PLATFORM
Security is built into how we design, deploy, and operate AI agents — scoped permissions, approval gates, complete audit trails, and certified cloud and payment platforms underneath.
SECURITY PRINCIPLES
Every layer of our platform is designed with security, privacy, and compliance in mind.
Multiple layers of security controls from infrastructure to application level.
Full audit logs of all AI agent actions, data access, and system changes.
Data encrypted in transit and at rest using industry-standard encryption.
Deployed on cloud providers with SOC 2 Type II and ISO 27001 attestations. Payments stay on Shopify's PCI DSS Level 1 checkout.
DATA PROTECTION
Comprehensive data protection measures from collection to deletion.
Data encrypted at rest using our cloud providers' managed encryption.
HTTPS/TLS for all traffic between services and clients.
Role-based access control (RBAC) with principle of least privilege.
Customer data logically isolated with strict separation between tenants.
Agents never handle payment card details. Checkout is handed off to Shopify.
Retention limits agreed per engagement, with data deletion on request.
AI GOVERNANCE
Our governance model makes AI agents safe for production commerce operations.
AI agents operate with explicitly defined permissions. No agent can access data or perform actions outside its scope.
Complete logs of all AI decisions, actions taken, data accessed, and reasoning used. Searchable and exportable.
High-risk actions require human approval. Define which operations need review before execution.
All agents tested against evaluation scenarios before deployment. No untested AI in production.
COMPLIANCE
We build on certified cloud and payment platforms, and we're explicit about which certifications belong to which provider.
Card data never touches our agents. Checkout is handed off to Shopify, a PCI DSS Level 1 certified service provider.
We support your obligations as data controller: data minimisation, agreed retention limits, and deletion on request.
Agents run on major cloud providers — AWS, Google Cloud, Azure, or Vercel — that hold these attestations. They cover our cloud providers, not Gwiksoft as a company.
We work within your security policies and access rules, and answer vendor security reviews as part of every engagement.
Running a vendor security review or need a DPA? security@gwiksoft.com
INFRASTRUCTURE SECURITY
The controls in place across infrastructure, access, and data.
INCIDENT RESPONSE
Clear commitments for handling security incidents and keeping affected clients informed.
We welcome responsible disclosure of security vulnerabilities. If you discover a security issue, please report it to:
security@gwiksoft.com
For security questions, vendor security reviews, DPA requests, or to report a vulnerability, contact our security team.
Response time: < 24 hours for security issues · < 72 hours for general inquiries